
Microsoft Sentinel
This integration is a part of other Microsoft integrations (Microsoft Defender for Office 365 and Microsoft Defender for Endpoint). This integration focuses on enterprise-wide security analytics, threat intelligence, and SIEM/SOAR capabilities.
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. Sentinel collects telemetry, security detections, and threat context from multiple products into one cloud location, and performs detection and analytics on that combined content from across the enterprise. In Cisco XDR, we enable Microsoft Sentinel users to include Cisco XDR incidents in that body of data, and to use Microsoft Sentinel in custom Automation routines in Cisco XDR.
When you add the Microsoft Sentinel integration into Cisco XDR, it enables Sentinel usage in Cisco XDR Automation for out-of-box and custom workflows including the ability to export Cisco XDR Incidents into Sentinel for seamless visibility spanning both products.
These are workflows that you can install in Cisco XDR automation and use with this integration. These are different from built-in workflows which are built into Cisco XDR by default for all customers.
These workflows are built into Cisco XDR automation and can be used with this integration. These are different from installable workflows, which are optional workflows you can install from Cisco and its partners.
These actions can be used in Cisco XDR automation to build workflows for this product. Workflows can help you automate how you investigate, respond to incidents, and more.




